Mixing App-ID and Service

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Mixing App-ID and Service

L4 Transporter

Am I correct in assuming that if you use App-ID you can't also use TCP sercice ports to allow aditiona other services on the same rule.

 

Thanks


Rob

5 REPLIES 5

Cyber Elite
Cyber Elite

@RobinClayton,

Actually that works perfectly fine as long as the app-id is actually coming across on that service port; I have to do it quite often for SQL enviroments actually. You would simply set the app-id to whatever is desired, say ( mssql-db mssql-mon ) and then set the service to whatever you are using in your enviroment; just keep in mind that this will only work if the firewall is identifying that traffic as that application. 

You could also create a custom app-id to match this traffic, or an application-override policy. This would allow you to maintain 'application-default' as the service depending on how much that matters to you. 

I am aware you can override the port the app usualy uses.

 

But what if I have say two items one with an application and one without.

 

"SMTP (Application 25) - "

"Other (No Application) - Service TCP46"

 

My findings are that it breaks.

@RobinClayton,

If you use app-id within the security policy and add a service that does not display that app-id it will break, as the traffic does not match the criteria of the rule. It doesn't really 'break', it's that the traffic doesn't actually match what is supplied by the security policy. If you are trying to pass traffic that doesn't map to an app-id (unknown-tcp or incomplete) you'll need to make a policy specifically for that traffic. Alternatively you could make a strict security policy that specifies an app-id of 'any' and then specify the service that needs to be allowed.  

Thanks, Confirms my findings.

 

 

Hello @RobinClayton,

I too have run across these issues, what I end up doing is creating two rules. One that matches the app-id and one with no app-id and just a service port.

 

Cheers!

  • 3088 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!